Welcome to Blaisdell's Little
Corner of the Web
More on Viruses
Albion
| Freeware | Freeware From A-Z
| Security
| Virus
Information | Updated 09/09/03
The Index
VIRUS SYMPTOMS
What should you look for
With all this talk about viruses, people still wonder: How
do you know if you have one? Everyone expects an executed virus to flash
skull-and-crossbones on the monitor while a disturbing laugh wells from the depths of the
hard drive. In truth, much of the time it can be difficult to tell if your computer is
infected. There are a few symptoms to watch out for. If you notice any of these things
happening on your computer, it's worth running your scanning software.
- Your computer seems to run much slower.
- Files disappear from your hard drive without explanation.
- The modification or creation dates on your files don't seem accurate.
- The size of files or programs increases greatly without explanation.
- Your RAM is nearly full and you're not sure why.
THE SYMANTEC VIRUS CALENDAR
Many viruses have a specific date on which to deliver their
"payload" (the destructive part of the program, as opposed to the part that
deals with self-replication.) Symantec maintains an online calendar that keeps user
up-to-date on upcoming dates when viruses are scheduled to execute destructive commands.
If you think you've been infected and you want to know what to look for, check out
http://www.symantec.com/avcenter/calendar/
More viruses for you to check out
- Check out Kournikova
cornucopia by Rob
Rosenberger
Note: The Myths.com site is temporarily down. If you get a message that the site cannot be
found, try the Urban Legends
and Folklore site instead. For more on the "AnnaKournikova" Worm, please see Symantec
or McAfee Thanks Denise for the broken link report,
very much appreciated....Bo
- APStrojan
- Melisssa
X or Melissa 2001
- W97M.Melissa.W
- Hahaha
Worm Is No Laughing Matter
Alias Hahaha and Snow White, this complex worm updates itself via the Internet. Reports of
infection are increasing wordwide
Hybris (W95.Hybris.gen)
is a complex supervirus whose e-mail delivery system is similar to Happy 99 and whose
programming and payload are similar to MTX.
- Click here for the top Viruse
- MTX Virus wont
let victims get help A computer virus thats smart enough to block its victims from
getting help is steadily spreading around the Internet.
- W32.Kriz
More on Kriz here
Click here
to begin the online scan. If you already know you are infected, proceed directly to
the W32.Kriz Removal
Tool.
- VBS/Forgotten
Read an emal, get infected.
- Prolin-The
pro-Linux "Prolin" virus -- which infects only Windows-based computers --
arrives in e-mail posing as a Shockwave movie.
- W32.BleBla
(alias MyRomeo, MyJuliet, Verona) hails from Poland and automatically executes upon
preveiwing or reading the infected HTML enchanced e-mail.
- W32/ProLin@MM
- Romeo and Juliet
bug a low risk
- Navidad, Hybris viruses
on the loose
- W32/Navidad@M
- Sonic.Worm Approaching
A new virus is spreading throughout Europe and is heading
towards the US. Batten down the hatches and update your anti-virus files to avoid its
destruction click here for a
full report from ZdNet Updates.com
The Perpetrator Sonic.
Worm will arrive as an e-mail message that has the following subject: Choose Your Poison, or I'm your poison
The virulent part of the e-mail is an executable attachment named:
girls.exe, or lovers.exe
If you are unlucky enough to launch the executable, the following text will be
displayed in a Windows message box:
"girls.exe is not a valid Win32 application.",
or "lovers.exe is not a valid Win32 application."
Sonic will copy itself to the Windows system directory as a file called GDI32.exe and install itself in the System
Registry under the Run Key as HKLM\Software\Microsoft\Windows\Current
Version\Run\"GDI"=C:\Windows\System\GDI32.exe
- New Love Bug virus a low risk
- DonaldD.trojan
is spreading, but not in U.S.
- Palm.Liberty.A
- Destructive
Palm program discovered
Microsoft's Security Patches and where you
can get your copy
- VBS.Forgotten.A@mm
- W32.Music.A.Worm
- X97M.Codemas.C
- XF.Sic
- W32.XTC.Worm
- W32.Blebla.B.Worm
- W32.Navidad
Removal
- W32.HLLW.QAZ.A
Removal
- W95.MTX Removal
- PWSteal.Trojan
Removal
- W32.FunLove.4099
Removal
- Wscript.Kakworm
Removal
- The Kak Help Center provides
instructions
for cleaning a Kak infection and
preventing future infections from occurring.
The List Continued from Page I
- Backdoor.Gholame
- W32.Golsys.14292
W32.Nios.14292
- W32.Manymize@mm
WORM_MANYMIZE.A [Trend], Win32.Manymize [CA], I-Worm.Manymize [AVP
- W32.Datom.Worm
W32/Datom-A [Sophos], Win32.Datom [CA], W32/Datom.worm [McAfee], Datom [F-Secure],
Worm.Win32.Datom [AVP]
- W97M.Saver.G
- W32.Lavehn.A@mm
- W32.Kitro.E.Worm
- Backdoor.Ducktoy
- W32.Supova.B.worm
- BAT.Eversaw.B@mm
- W32.Frethem.K@mm
- W32.Frethem.J@mm
- W32.Wabbin
- W32.Nuker.Winskill
- W32.Urick.A@mm
WORM_URICK.A [Trend]
- Banan.Trojan
- W32.Click
- W32.Liac.A@mm
W32.Liac@mm, WORM_LIAC.A [Trend], W32/Calil-A [Sophos], W32/Liac@MM [McAfee]
- Liquid.Trojan
- XM.ZePast.A
- VBS.Slip.C@mm
- Backdoor.Assasin
- W32.Kitro.C.Worm
- W32.HLLW.Kazmor
- Backdoor.NetControle
- W32.Kwbot.Worm
- W32.Yaha.F@mm
WORM_YAHA.E, Worm/Lentin.F
- BAT.Beckow.Worm
BAT_NOWE.A, Worm/BWG.E
- W32.Yaha.E@mm
W32.Yaha.D@mm
- Backdoor.Sazo
- W97M.Twopey.A
- VBS.Krim.B
- W32.Higuy@mm
W32/Higuy-A, W32/Higuy@MM, WORM_HIGUY.A
- Trojan.Allclicks.A
TrojanClicker.NetBuie.a, Trojan/Win32.Elitec, Trojan.NetBuie.A
- W32.Yaha.E@mm
- PHP.Alf
- W32.Estrella
- Backdoor.Ultor
- W97M.Nori.A
Macro.Word97.Nori
- W97M.Locus
- W32.Perrun
W32/Perrun-A, PE_PERRUN.A, Win32.Perrun, W32/Perrun, Perrun, W32/Perrun.A
- Backdoor.Nota
- Backdoor.Dewin
- X97M.Trevir
- VBS.Slip@mm
- Backdoor.Crat
- BAT.WCup@mm
- W32.Frethem.E@mm
- W32.Alcarys.G@mm
WORM_NEYSID.A, W32.Neysid@mm, W97M.Alcarys.G@mm, W97M.Neysid@mm, X97M.Alcarys.G@mm,
X97M.Neysid@mm
- Backdoor.FTP_Bmail
Backdoor.FTP.Bmail(AVP), BackDoor-ABH (McAfee)
- {Win32,Linux}/Simile.D
- W32.Frethem.D@mm
- W32.Fishlet.A@mm
- W32.Chir@mm
W32.Chier@mm
- VBS.Chick.F@m
- Backdoor.AntiLam
I-Worm.Brit-G, World Cup, VBS/Chick-F, VBS_CHICK.F, VBS/Chick.f@M
- Backdoor.Latinus
- W32.HLLW.Nople
- VBS.VBSWG.AQ@mm
VBS/VBSWG.aq@MM, VBS_VBSWG.AQ, VBS/VBSWG-AQ, VBSWG.AQ
- Backdoor.Tron
- W32.Pet_Ticky.B@mm
- Backdoor.GSpot
- W32.Frethem.B@mm
- W32.Frethem.A@mm
- W32.Benjamin.Worm
- X97M.Draco
- W97M.Sacep.B
- W32.Hedong.A@mm
- W32.Seesix.Worm
- Trojan.Prova
- W32.Tendoolf
- W95.CIH.1049
- Trojan.Fatkill
- Backdoor.Evilbot
- Backdoor.RemoteNC
- W32.DSS.Trojan
- W32.Maldal.K@mm
- W32.Elkern.4926
- W32.Klez.H@mm
- W32.Klez.gen@mm
- W32.Trilisa@mm
- W97M.Destrib
- HTML.Redlof.A
- X97M.Divi.O
- ABAP.Rivpas.A
- W32.Aphex@mm
- W32.Aplore@mm.
- W32.Mylife.I@mm
- W32.Mylife.J@mm
- W97M.Mxfile.L.gen
- VBS.Resreg@mm
- VBS.Chick.C@mm
- W32.Hunch.C@mm
- W32.MyLife.G@mm
- W97M.Cisi.A
- W32.Maldal.J
- W32.MyLife.F@mm
- DynHTML.Exploit
- VBS.Annod.B
- Backdoor.Delf
- Backdoor.Delf.C
- Backdoor.Delf.B
Backdoor.Delf.bv
- Backdoor.Kavar
- BAT.Krazyb.A@mm
BAT_KRAZYB.A [Trend]
- PWSteal.Netsnake
- PWSteal.Kaylo
Trojan.PSW.Kaylo [AVP], TROJ_PSW.KAYLO.A [Trend], PWS-Kaylo [McAfee]
- PWSteal.Profman
Trojan.PSW.Profman [AVP], TROJ_PROFMAN.C [Trend], PWS-Profman [McAfee]
- VBS.Neiber.A@mm
VBA_NEIBER.A [Trend]
- Trojan.Crabox
- Trojan.Starfi
- Backdoor.Tela
- FakeGina.Trojan
- W32.Azak
- Trojan.Adnap
|
- Backdoor.Easyserv
Backdoor.Easyserv.11
- Trojan.Portacopo:br
- XM.Laroux.ST
- Wyx.C (b)
- W32.Mortag
- W97M.Bablas.AT
- W97M.Alarm
- Backdoor.WinShell
- W32.Assarm@mm
- W32.AJM.Worm
- W32.HLLW.Lama
- IRC.kierz
- W32.Golsys.8020
- W32.HLLW.Kazmor.C
- VBS.Sealug@mm
- W32.Kamil
- W32.BleBla.J.Worm
- Trojan.Junnan
- W32.HLLW.Sambut
- W32.HLLW.Yoohoo
W32.HLLW.Spear, W32.HLLW.Yoohoo.B
- W32.Kotef
- W97M.Peddec.A
- W32.Fully.3424
- W32.HLLP.Sharpei@mm
- W32.Rexli.A@mm
- W97M.DebilByte.A
- W97M.Comical@mm
- W97M.Nomed.A
- Backdoor.DSNX
- W32.Porma@mm
- W32.Hunch@mm
- W32.Sysnom.C@mm
- W32.Nimda.A@mm
- Backdoor.Y3KRat.12
- DonaldD.Trojan.C
- Umisy.2322
- Trojan.ZeroBoot
- W95.Tabeci.2683
- W97M.Cerin.A
- VBS.Masteal.Trojan
- Septer.Trojan
- W32.Redesi@mm
- Backdoor.Litmus
- VBS.Loveletter.CV@mm
- VBS.VBSWG.AF
- VBS.Lee@mm
I-Worm.Lee.b, VBS/Pica.worm.gen
- Backdoor.IRC.Critical
- W32.Nimda.C@mm
- W32.JavaKiller.Trojan
Trojan.W32.JavaKiller
- W97M.Grac.A
- W97M.Thelar.A
- Backdoor.Slackbot.B
- W32/Nimda@MM
- W32.HLLP.Gosusub
- W32.Whitebait@mm
- W32.Myparty.B@mm
- W32.Myparty@mm
W32/Myparty@MM, WORM_MYPARTY.A, W32/MyParty-A, Win32.MyParty,
I-Worm.Myparty
- VBS.Funcess
- W32.Led@mm
W32/Fagled@MM, Win32.Fagled
- W97M.Pacol.A
W97M.Wassoc.Trojan
- VBS.Manis@mm
- W97M.Doeii
- W32.ElKern.3587
W32.ElKern.B
- W32.Klez.E@mm
- W97M.Fifteen
- W32.Fisp
- HLLP.Saywat.7499
- W32.Enviar.gen
W32.TempX.A@m
- X97M.ROH.A
- Trojan.StartPage
- Trojan.Badcon
- W32.Spester@mm
- Hacktool.IPStealer
- JS.Gigger.A@mm
- W32.Donut
- W32.LastScene@mm
VBS.Scene
- ACTS.LFM.926
SWF.LFM.926
- W32.Toget@mm
W32.Steatopygous@mm
- JS.Seeker.F
- Backdoor.Palukka
- W32.Shatrix@mm
- W32.Maldal.D@mm
- W32.DlDer.Trojan
- W32.Zoher@mm
- W32.Shoho@mm
- W32.Maldal.C@mm
- JS.Coolsite@mm
- w32.Reeezak.a@mm
- W32.Maldal.C@mm
- JS.Coolsite@mm
- X97M.Brep
- W32.Gokar.A@mm
- VBS.Elliv
- Trojan.Danschl.A
- W97M.Jishe.D
- W32.Goner.A@mm
- W32.Eira.57344@mm
- VBS.Alal
- W32.Badtrans.B@mm
- W32.Elem.Trojan
- W32.Cblade.Worm
- VBS.Snav
- W32.Nimda.A@mm
- W32.Sircam.Worm@mm
- W32.Aliz.Worm
- VBS.Haptime.A@mm
- W32.Magistr.24876@mm
- W32.HLLW.Bymer
- W95.Hybris.Gen
- W95.MTX
- Wscript.KakWorm
- Bin.Auto.ARC
- Bin.Auto.ARD
- Bin.Auto.ARE
- Bin.Auto.ARF
- Bin.Auto.ARG
- Bin.Auto.ARH
- Bin.Auto.ARI
- Bin.Auto.ARJ
- Bin.Auto.ARK
- Bin.Auto.ARL
- Bin.Auto.ARM
- Phreak.Trojan
- W32.Paukor@mm
- VBS.Lanus.gen
- IRC.Becky.A
- Mac.Simpsons@mm
- Backdoor.MLink
- Backdoor.Fearic
Backdoor.Fear.15 [AVP]
- Bneo.Trojan
MSN.Trojan
- Trojan.Lovead
Trojan.W32.Loveadot.f [AVP], Adshow [Mcafee]
- Backdoor.Scanboot
- Trojan.MSNTrick
- W97M.Creutze
Macro.Word97.Creutze [AVP], W97M/Creutze.A [F-Prot]
- W32.Mylife.M@mm
W32.Mylife@mm, WORM_HARAS.A [Trend]
- W97M.Maike
- IIS.Beavuh-Exploit
- Prophecy.Worm
- Netbus.160.Dropper
|
|
How a Boot Sector Virus works
It makes no difference to a boot sector virus whether a floppy disk is bootable or not,
contains only data files, or even has no files. To this type of virus, the boot sector is
what's important. Here's how they work. At bootup, if an infected floppy is in drive A,
the PC's BIOS will read the boot sector (or a virus written there) into memory first, even
before the operating system (or an antivirus program) is loaded into memory.
At that point, a virus can be spread from an infected floppy disk to the hard disk. The
process is almost instantaneous: The virus program in the floppy's boot sector is read,
then it takes control of memory--and most boot-sector viruses will infect the hard disk
immediately. If the floppy is not bootable, the boot process may halt, usually with a
Non-System Disk message, but the virus is in memory nevertheless and can spread, usually
by copying to the hard disk's boot sector or to its MBR (master boot record).
By infecting those areas of the hard disk, this type of virus will be loaded into
memory every time the PC is turned on, even before the operating system is loaded. This
gives the virus an opportunity to start the cycle over, by copying to more floppy disks,
as they're passed from user to user.
Latest Headlines
The BadTimes Virus
If you receive an email entitled "Badtimes", delete it immediately. Do not
open it. Apparently this one is pretty nasty. It will not only erase everything on your
hard drive, but it will also delete anything on disks within 20 feet of your computer.
- It demagnetizes the stripes on ALL of your credit cards.
- It reprograms your ATM access code, screws up the tracking on your VCR and uses subspace
field harmonics to scratch any CD's you attempt to play.
- It will program your phone auto dial to call only 900 numbers.
- This virus will mix antifreeze into your fish tank.
- It will drink ALL your beer.
FOR GOD'S SAKE, ARE YOU LISTENING!?!?!?
- It will leave dirty underwear on the coffee table when you are expecting company.
- It will replace your shampoo with Nair and your Nair with Rogaine, all the while dating
your current boy/girlfriend behind your back and billing their hotel rendezvous to your
Visa card.
- It will cause you to run with scissors and throw things in a way that is only fun until
someone loses an eye.
- It will rewrite your backup files, changing all your active verbs to passive tense and
incorporate undetectable misspellings which grossly change the interpretations of key
sentences.
- If the "Badtimes" message is opened in a Windows 95/98 environment, it will
leave the toilet seat up and leave your hair dryer plugged in dangerously close to a full
bathtub.
- It will not only remove the forbidden tags from your mattresses and pillows, it will
also refill your skim milk with whole milk.
**WARN AS MANY PEOPLE AS YOU CAN!!
Thank you for stopping by.
Some resources to check to see if that warning you
got in your email is real or just another hoax.
- Symantec's Hoaxes
page.
- Urban Legends Reference Pages.
- Inboxer
Rebellion page.
- ZDNet Help & How-To's E-Hoax
Central.
- McAfee.com's Virus Hoax
- Hoaxbusters
Five tip-offs that you might be looking at a hoax:
- It's forwarded from a friend of a friend of an acquaintance of your boss's second
cousin's dentist
- It's badly punctuated with TOO MANY CAPITAL LETTERS and exclamation points!!!!!!!
- It starts out by saying, "This is not a hoax!"
- It warns of dire results, such as crashing your entire hard drive or causing economic
chaos
- It asks you to forward the letter to everyone you know.